What the vulnerability does
01Description
Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.
Explanation of Vulnerability in Simple Terms
The Booking Package contains a privilege management flaw that allows an unauthenticated attacker to gain unauthorized access to sensitive functions. The vulnerability requires user interaction, such as clicking a malicious link. An attacker can read, modify, or delete booking data and other site information. All versions up to 1.5.98 are affected.
What an attacker can do
Read, modify, or delete booking data and other sensitive site information without authorization.
Potential impact on your site
Booking records, customer data, and site functionality can be compromised without authentication.
Conditions required to exploit
Attacker must trick a user into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities